CISA-KR 문제 416
One of the key activities of a configuration management system is to define baselines for software. A baseline is a fixed reference point that serves as a basis for comparison and measurement. A baseline can be established for any configuration item, such as a requirement, a design document, a test plan, or a software component. A baseline helps to ensure that the software product meets its intended purpose and quality standards, and that any changes to the software are controlled and documented.
A configuration management system also supports other activities, such as tracking software updates, supporting the release procedure, and standardizing change approval, but these are not its primary purpose.
Therefore, the other options are incorrect.
References: : What is configuration management - Red Hat : Configuration Management | Definition, Importance & Benefits - ServerWatch
CISA-KR 문제 417
이 상황에서 가장 큰 우려 사항은 다음 중 무엇입니까?
CISA-KR 문제 418
Inadequate or unclear service level agreements (SLAs) that do not specify the quality, timeliness, and accuracy of the payroll service.
Insufficient or vague security and confidentiality provisions that do not safeguard the client's data and information from unauthorized access, use, disclosure, or loss.
Unreasonable or excessive fees, penalties, or liabilities that may impose an undue financial burden on the client.
Limited or no audit rights that may prevent the client from verifying the effectiveness and compliance of the payroll provider's internal controls.
Inflexible or restrictive termination clauses that may limit the client's ability to cancel or switch to another payroll provider.
A third-party contract that has not been reviewed by the legal department may expose the client to various risks, such as:
Legal disputes or litigation with the payroll provider over contractual breaches or performance issues.
Regulatory fines or sanctions for noncompliance with tax, labor, or other laws and regulations related to payroll.
Financial losses or damages due to errors, fraud, or negligence by the payroll provider.
Reputation damage or customer dissatisfaction due to payroll errors or delays.
Therefore, an IS auditor should be highly concerned about a third-party contract that has not been reviewed by the legal department and recommend that the client seek legal advice before signing or renewing any contract with an outsourced payroll provider.
User access rights have not been periodically reviewed by the client is a moderate concern because it may indicate a lack of proper access control over the payroll system. User access rights are the permissions granted to users to access, view, modify, or delete data and information in the payroll system. User access rights should be periodically reviewed by the client to ensure that they are aligned with the user's roles and responsibilities, and that they are revoked or modified when a user changes roles or leaves the organization.
User access rights that are not periodically reviewed by the client may result in unauthorized or inappropriate access to payroll data and information, which may compromise its confidentiality, integrity, and availability.
Payroll processing costs have not been included in the IT budget is a minor concern because it may indicate a lack of proper planning and allocation of IT resources for payroll processing. Payroll processing costs are the expenses incurred by the client for using an outsourced payroll service, such as fees, charges, taxes, or penalties. Payroll processing costs should be included in the IT budget to ensure that they are adequately estimated, monitored, and controlled. Payroll processing costs that are not included in the IT budget may result in unexpected or excessive costs for payroll processing, which may affect the client's profitability and cash flow.
The third-party contract does not comply with the vendor management policy is a low concern because it may indicate a lack of alignment between the client's vendor management policy and its actual vendor selection and evaluation process. A vendor management policy is a set of guidelines and procedures that governs how the client manages its relationship with its vendors, such as how to select, monitor, evaluate, and terminate vendors. A vendor management policy should be consistent with the client's business objectives, risk appetite, and regulatory requirements. A third-party contract that does not comply with the vendor management policy may result in suboptimal vendor performance or service quality, but it does not necessarily imply a breach of contract or a violation of law.
CISA-KR 문제 419
CISA-KR 문제 420
Misconfiguration refers to any deviation from the recommended or best practice settings for the network devices, such as weak passwords, open ports, unnecessary services, default accounts, or incorrect permissions. Missing updates refer toany outdated or unsupported software or firmware that has not been patched with the latest security fixes or enhancements from the vendors2. Misconfiguration and missing updates are common sources of network vulnerabilities that can be exploited by attackers to gain unauthorized access, executemalicious code, causedenial of service, or escalate privileges on the network devices3.
Therefore, an IS auditor should expect to see misconfiguration and missing updates in a network vulnerability assessment. The other options are less relevant or incorrect because:
* B. Malicious software and spyware are not usually detected by a network vulnerability assessment, as they are more related to the content and behavior of the network traffic rather than the configuration and patch level of the network devices. Malicious software and spyware are programs that infect or monitor the network devices or their users for malicious purposes, such as stealing data, displaying ads, or performing remote commands. Malicious software and spyware can be detected by other security tools, such as antivirus software, firewalls, or intrusion detection systems4.
* C. Zero-day vulnerabilities are not usually detected by a network vulnerability assessment, as they are unknown or undisclosed vulnerabilities that have not been reported or patched by the vendors or the security community. Zero-day vulnerabilities are rare and difficult to discover, as they require advanced techniques and skills to exploit them. Zero-day vulnerabilities can be detected by other security tools, such as intrusion prevention systems, anomaly detection systems, or artificial intelligence systems5.
* D. Security design flaws are not usually detected by a network vulnerability assessment, as they are more related to the logic and functionality of the network rather than the configuration and patch level of the network devices. Security design flaws are errors or weaknesses in the network architecture, design, policies, or procedures that could compromise the security objectives of the network. Securitydesign flaws can be detected by other security methods, such as security reviews, audits, or assessments6. References: Network VulnerabilityAssessment - ISACA, Network Vulnerability Scanning - NIST, Network Vulnerabilities - SANS, Malware - ISACA, Zero-Day Attacks
- ISACA, Security Design Principles - NIST
- 다른 버전
- 326ISACA.CISA-KR.v2026-08-15.q712
- 4338ISACA.CISA-KR.v2026-05-16.q709
- 1872ISACA.CISA-KR.v2026-05-06.q261
- 3347ISACA.CISA-KR.v2026-03-16.q665
- 4745ISACA.CISA-KR.v2026-03-07.q651
- 9449ISACA.CISA-KR.v2025-04-07.q633
- 3811ISACA.CISA-KR.v2025-04-02.q544
- 4317ISACA.CISA-KR.v2025-03-31.q534
- 5531ISACA.CISA-KR.v2025-03-28.q617
- 3316ISACA.CISA-KR.v2025-03-19.q581
- 4199ISACA.CISA-KR.v2025-03-03.q807
- 5246ISACA.CISA-KR.v2024-02-07.q421
- 2940ISACA.CISA-KR.v2024-01-31.q392
- 5443ISACA.CISA-KR.v2023-10-24.q329
- 5262ISACA.CISA-KR.v2023-07-31.q266
- 3261ISACA.CISA-KR.v2023-06-23.q324
- 최근 업로드
- 144Microsoft.AZ-305-KR.v2026-08-17.q162
- 153IIA.IAA-IAP-KR.v2026-08-17.q41
- 326ISACA.CISA-KR.v2026-08-15.q712
- 259Microsoft.MS-700-KR.v2026-08-15.q203
- 182Microsoft.AZ-305-KR.v2026-08-14.q177
- 258Microsoft.DP-900-KR.v2026-08-13.q130
- 322Microsoft.PL-600.v2026-08-11.q206
- 287Microsoft.DP-100.v2026-08-11.q160
- 212Oracle.1Z0-1048-25.v2026-08-11.q68
- 180ISQI.CTAL-TAE.v2026-08-11.q37
PDF 파일 다운로드
메일 주소를 입력하시고 다운로드 하세요. ISACA.CISA-KR.v2025-04-03.q628 모의시험 시험자료를 다운 받으세요.
